CVE-2024-41236

HIGH

Kashipara Responsive School Management System v3.2.0 - SQL Injection via Admin Login Username Parameter

Title source: llm
STIX 2.1

Description

A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page

Scores

CVSS v3 7.2
EPSS 0.0037
EPSS Percentile 29.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
lopalopa/responsive_school_management_system 3.2.0
Published Aug 28, 2024
Tracked Since Feb 18, 2026